ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise

ASEC June 2026 APT Trend Report (TL-2026-1287), also tracked as ASEC June 2026 APT Trend Report, is a medium-severity campaign, first published 2026-07-14. It is attributed to APT38 (North Korea, China, Russia, Iran) with high confidence, affects Microsoft Microsoft Office, references 1 CVE (CVE-2026-21509), maps to 30 MITRE ATT&CK techniques (T1005, T1014, T1016), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-1287

Threat ID
TL-2026-1287
Also known as
ASEC June 2026 APT Trend Report, APT Group Threat Report - June 2026
Severity
MEDIUM
Status
ACTIVE
Category
CAMPAIGN
First published
2026-07-14
Last reviewed
2026-07-14
Attribution
APT38
Attribution confidence
HIGH
Nation-state nexus
North Korea, China, Russia, Iran
Motivation
ESPIONAGE
Target sectors
government administration, diplomacy, defense, medical-research, energy, finance, telecom, transport, software-development, retail-investors
Target regions
ukraine, india, pakistan, china, south korea, vietnam, cambodia, israel, Middle East, united states of america, Europe
Detection rules
9
Indicators of compromise
24

Malware and tooling in ASEC June 2026 APT Trend Report

Malware and tooling: ChainShell, INFINITERED, NIGHTFORGE, NarwhalRAT, NightshadeC2 (Windows), PixyNetLoader, SHARDLOADER, SPECTRALVIPER, STOCKSTAY, SprySOCKS, X-Agent, XTunnel

AhnLab ASEC's June 2026 APT trend digest tracks 20 nation-state groups (North Korea, China, Russia, Iran, India/Southeast Asia) converging on a shared modern playbook: OAuth token theft, abuse of legitimate cloud services (Google Drive, Dropbox, pCloud, Zoho WorkDrive, FILEN) for C2/delivery, npm and vendor-update supply-chain compromise, and adoption of criminal malware-as-a-service platforms such as CastleRAT.

How ASEC June 2026 APT Trend Report works

AhnLab Security Emergency response Center (ASEC) published a monthly APT trend report on 2026-07-14 covering June 2026 activity from 20 tracked nation-state groups. The report is a digest-level roundup rather than a single-incident advisory: it names threat actors, malware families, and TTP categories per region without providing raw IOCs, CVEs, or CVSS scores for the digest itself. Follow-on research against the individually cited campaigns (independently reported by Microsoft, Google/Mandiant, ESET, ThreatLabz/Zscaler, Trellix, and CISA) supplies the technical depth: North Korea's Sapphire Sleet compromised the @mastra npm organization on 2026-06-17, backdooring 140+ packages (combined 1.1M+ weekly downloads) via a typosquatted 'easy-day-js' dependency with an obfuscated postinstall dropper; APT37/ScarCruft deployed the Python-loader-based NarwhalRAT via fake Microsoft security-alert phishing; China-nexus FishMonger (tracked historically as Earth Lusca/Aquatic Panda/Bronze University/Charcoal Typhoon/RedHotel) ported the Linux SprySOCKS backdoor to Windows with a kernel-driver rootkit and UEFI bootkit indicators, while other China-nexus clusters (UNC6508 et al.) abused Zoho WorkDrive as C2 infrastructure and OAuth tokens for persistent access to victim government, diplomatic, medical-research, and energy-sector environments; Russia's APT28 (Fancy Bear) ran Operation Neusploit exploiting CVE-2026-21509 in Microsoft Office to deliver PixyNetLoader, which hides shellcode in PNG images via LSB steganography and achieves persistence through COM object hijacking, while Turla (Secret Blizzard) deployed the KAZUAR-derived .NET/WebSocket backdoor STOCKSTAY against Ukrainian government/military and Italian-diplomacy-themed targets; Iran's MuddyWater (tied to Iran's MOIS) was found operating at least two builds of the Russian-developed CastleRAT malware-as-a-service platform alongside a new JavaScript/Node.js implant, ChainShell, that resolves its C2 address from an Ethereum smart contract and communicates over AES-encrypted WebSockets, discovered via an open C2 directory listing containing Farsi comments and Israeli IP-range target lists (Ctrl-Alt-Intel, 2026-03-04); and Vietnam-aligned OceanLotus (APT32) ran a supply-chain compromise of the FireAnt MetaKit stock-investment platform's update server (Oct 2025-Mar 2026) to selectively deliver the SPECTRALVIPER backdoor to Vietnamese stock investors. Collectively the report documents a strategic shift away from bespoke malware-only operations toward abuse of legitimate developer and cloud infrastructure, criminal MaaS procurement, and supply-chain trust exploitation across all tracked regions.

MITRE ATT&CK techniques used in TL-2026-1287

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Defense Evasion

T1014 Rootkit; T1027.003 Steganography; T1140 Deobfuscate/Decode Files or Information; T1542.003 Bootkit

Discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery

Execution

T1059.001 PowerShell; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1573.001 Symmetric Cryptography

Initial Access

T1190 Exploit Public-Facing Application; T1195.001 Compromise Software Dependencies and Development Tools; T1199 Trusted Relationship; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

initial-access

T1195.002 Compromise Software Supply Chain

Persistence

T1505 Server Software Component; T1546.015 Component Object Model Hijacking

Credential Access

T1528 Steal Application Access Token; T1555.003 Credentials from Web Browsers

Exfiltration

T1567.002 Exfiltration to Cloud Storage

stealth

T1574.001 DLL

Resource Development

T1583.006 Web Services; T1588.001 Malware; T1608 Stage Capabilities

Affected products and versions in ASEC June 2026 APT Trend Report

  • Microsoft — Microsoft Office
    Vulnerable versions: versions affected by CVE-2026-21509
    Fixed in: patched per Microsoft security update, see vendor advisory
  • Mastra AI / npm registry — @mastra npm package ecosystem (including @mastra/core) and easy-day-js dependency
    Vulnerable versions: packages republished 2026-06-17 with easy-day-js@1.11.21+ dependency
    Fixed in: packages republished after remediation removing easy-day-js dependency
  • FireAnt (Vietnam) — FireAnt MetaKit stock-investment platform update mechanism
    Vulnerable versions: update server compromised Oct 2025-Mar 2026
    Fixed in: update server remediated post-disclosure June 2026

Remediation for ASEC June 2026 APT Trend Report

Patches

  • Apply Microsoft Office security update addressing CVE-2026-21509

Immediate actions

  • Audit and revoke unused/overprivileged OAuth application tokens across Google Workspace, Microsoft 365, and other SSO-integrated SaaS
  • Restrict or monitor outbound traffic to consumer cloud-storage domains (Google Drive, Dropbox, pCloud, Zoho WorkDrive, FILEN) from endpoints that should not need them for C2-shaped patterns
  • Pin npm/package-manager dependencies with lockfiles and verify package provenance/signing before CI/CD install; block postinstall scripts in build pipelines where feasible
  • Patch Microsoft Office against CVE-2026-21509 (Operation Neusploit / APT28)

Workarounds

  • Block/quarantine easy-day-js and any Mastra package versions published between 2026-06-16 and 2026-06-19 pending provenance verification
  • Disable macro/COM auto-execution and restrict COM object registration paths where PixyNetLoader-style hijacking is a concern

Longer-term hardening

  • Deploy EDR with kernel-driver/rootkit detection and UEFI/firmware integrity attestation given SprySOCKS' Windows kernel-driver evolution
  • Implement software supply-chain integrity controls (SBOM, package signing, update-server code signing) for vendor auto-update mechanisms after the FireAnt MetaKit and Mastra npm compromises
  • Hunt for PNG/image steganographic payloads and COM-hijack persistence artifacts in environments exposed to Russian APT tooling
  • Monitor for AES-encrypted WebSocket C2 and blockchain-resolved (e.g., Ethereum smart-contract) C2 address patterns associated with MaaS platforms like CastleRAT/ChainShell

CVEs associated with ASEC June 2026 APT Trend Report

CVE-2026-21509

Weaknesses (CWE) in ASEC June 2026 APT Trend Report

CWE-506, CWE-494, CWE-287

Timeline of ASEC June 2026 APT Trend Report

  • APT28 (Fancy Bear) Operation Neusploit disclosed, exploiting CVE-2026-21509 in Microsoft Office to deliver the PixyNetLoader implant with PNG-steganography payload hiding and COM-hijacking persistence.
  • Researchers at Ctrl-Alt-Intel discover an open directory listing on a C2 server, assessed with high confidence to belong to Iran's MuddyWater, containing the ChainShell PowerShell deployer (reset.ps1), Farsi code comments, and Israeli IP-range target lists.
  • Public reporting links MuddyWater's use of the Russian-developed CastleRAT malware-as-a-service platform to the newly discovered ChainShell JavaScript/Node.js implant, which resolves its C2 address via an Ethereum smart contract over AES-encrypted WebSockets.
  • MuddyWater observed abusing Microsoft Teams to steal credentials in a false-flag ransomware operation.
  • North Korea's ScarCruft/APT37 deploys NarwhalRAT via spear-phishing messages impersonating Microsoft Account security notifications, staging data in a hidden %APPDATA%\naverwhale directory.
  • ESET researchers document a previously undocumented Windows variant of the SprySOCKS backdoor, attributed to China-nexus FishMonger, featuring a kernel-driver rootkit and UEFI bootkit indicators.
  • Google/Mandiant details Turla's (Secret Blizzard) new STOCKSTAY .NET/WebSocket backdoor, a KAZUAR-derived multi-component implant used against Ukrainian government/military and Italian-diplomacy-themed targets.
  • ESET/OceanLotus (APT32) reporting reveals a supply-chain compromise of the FireAnt MetaKit stock-investment platform update server (active October 2025-March 2026), delivering the SPECTRALVIPER backdoor to a selective subset of Vietnamese stock investors.
  • npm user 'sergey2016' publishes easy-day-js@1.11.21, a clean-looking typosquat of the dayjs library mimicking its metadata, used as bait for the subsequent Mastra compromise.
  • Attacker compromises the @mastra npm organization and republishes 140+ packages (combined 1.1M+ weekly downloads) with easy-day-js added as a production dependency carrying an obfuscated postinstall dropper.
  • Microsoft attributes the Mastra npm supply-chain campaign to North Korea's Sapphire Sleet group, citing infrastructure and post-compromise TTP overlap with prior Axios package compromise activity.
  • AhnLab ASEC publishes its June 2026 APT trend digest synthesizing the above campaigns across 20 tracked nation-state groups spanning North Korea, China, Russia, Iran, and India/Southeast Asia.

Sources cited for ASEC June 2026 APT Trend Report

Threats related to ASEC June 2026 APT Trend Report

Detection coverage for TL-2026-1287

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1287 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats